{"record":{"id":"a62949680d00a22f","repo":"Hmbown/CodeWhale","slug":"error-additionally-the-codewhale-owned-legacy-slot-secret","errorCode":null,"errorMessage":"{error}; additionally the Codewhale-owned legacy {slot} secret slot changed concurrently and was not overwritten during rollback","messagePattern":"(.+?); additionally the Codewhale-owned legacy (.+?) secret slot changed concurrently and was not overwritten during rollback","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"critical","filePath":"crates/cli/src/lib.rs","lineNumber":2726,"sourceCode":"    }\n\n    if let Err(error) = store.save() {\n        store.config = original_config;\n        if let Some(previous) = prior_secret {\n            let current = secrets.get(slot).map_err(|rollback| {\n                anyhow!(\n                    \"{error}; additionally could not verify rollback of the Codewhale-owned legacy {slot} secret slot: {rollback}\"\n                )\n            })?;\n            match current {\n                None => secrets.set(slot, &previous).map_err(|rollback| {\n                    anyhow!(\n                        \"{error}; additionally failed to restore the Codewhale-owned legacy {slot} secret slot: {rollback}\"\n                    )\n                })?,\n                Some(current) if current == previous => {}\n                Some(_) => {\n                    return Err(anyhow!(\n                        \"{error}; additionally the Codewhale-owned legacy {slot} secret slot changed concurrently and was not overwritten during rollback\"\n                    ));\n                }\n            }\n        }\n        return Err(error);\n    }\n\n    codewhale_config::scrub_plaintext_api_keys_from_config_backup(store.path())?;\n    codewhale_config::scrub_legacy_antigravity_from_config_backup(store.path())?;\n    println!(\n        \"cleared Codewhale-owned legacy Antigravity config, consent, selection, fallback entries, and secret-store slot; Google and Antigravity sessions were not read, revoked, or changed. For Gemini, configure provider google and set GEMINI_API_KEY\"\n    );\n    Ok(())\n}\n\nfn provider_env_set(provider: ProviderKind) -> bool {\n    provider_env_value(provider).is_some()","sourceCodeStart":2708,"sourceCodeEnd":2744,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/73e0f67d83c59909b571efdfc88c4bc28c309cb1/crates/cli/src/lib.rs#L2708-L2744","documentation":"During rollback of the Codewhale-owned legacy secret slot, the code re-reads the current slot value and refuses to overwrite it if it changed concurrently. This guard prevents clobbering a value another process wrote while rollback was in flight. The error surfaces instead of silently overwriting live data.","triggerScenarios":"While a failed operation is being rolled back, another process or CLI instance writes a new value into the same legacy secret slot, so current != previous and the rollback refuses to proceed.","commonSituations":"Two instances of the CLI (or an updater and a running session) racing over the same credential slot; a scheduled token-refresh daemon updating the secret during a migration rollback.","solutions":["Ensure only one CLI/updater instance operates on the secret slot at a time (close other sessions, stop background refresh).","Decide which value is correct; manually set the slot if the concurrent write should be kept.","Re-run the operation after the concurrent writer is gone.","If the concurrent value is stale, delete it and let the retry re-establish the previous value."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// before rolling back, check the slot is untouched\nlet current = secrets.get(slot)?;\nif current.as_deref() != Some(previous.as_str()) {\n    eprintln!(\"slot changed concurrently; resolve manually before rollback\");\n}","typeGuard":null,"tryCatchPattern":"match result {\n    Err(ConcurrentSlotWrite) => {\n        // prompt user: keep new value or force restore\n    }\n    other => other,\n}","preventionTips":["Serialize all secret-slot writes through one process or lock.","Disable background credential refresh during update/migration.","Re-read the slot immediately before writing to detect races early."],"tags":["secrets","concurrency","race-condition","rollback"],"backgroundTag":"invalid-state-transition","analyzedSha":"73e0f67d83c59909b571efdfc88c4bc28c309cb1","analyzedAt":"2026-09-22T01:30:00.501Z","contentChangedAt":"2026-09-22T01:30:00.501Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}